A user on the online forum 4chan has leaked a massive 270GB of data belonging to The New York Times. This leak includes the source code for the newspaper’s digital operations.

Here are some other findings we can confirm:

  • The leak does have the original source code of the game Wordle, which the NY Times acquired in 2022.
  • The leak includes a dated WordPress database of 1,500 NY Times Education site users. The database contains names and surnames, email addresses, and hashed passwords. You should expect it to be added to HIBP shortly.
  • Several folders contain internal communications from NY Times Slack channels.
  • Times uses various machine learning algorithms and NLP techniques/scripts for its services.
  • Many exposed authentication methods exist, including authentication URLs and their respective passwords, secret keys, and API tokens. The majority are well protected, but plenty of such secrets need immediate attention. We have also seen private user keys used for authentication.
  • There are a lot of details about internal NY Times architecture from a software development point of view.

So far, it is difficult to say whether the NY Times will need to reset the passwords for everyone who is a member of its site.

It’s worth pointing out that this leak appears to involve data from The New York Times’s IT/infrastructure/website organization rather than the news organization composed of reporters. In media companies, these two entities are largely separate. The IT/infrastructure team handles the technical aspects of the website and digital operations, while the news organization manages reporting and editorial content.

    • chickentendrils [any, comrade/them]
      link
      fedilink
      English
      33
      edit-2
      5 months ago

      Something weird about that figure. Branches within repos maybe, otherwise those are mostly junk or their supply chain attack security requirements had them cloning and building themselves the repos of every open source library they’ve ever used for vulnerability scans.

    • glans [it/its]
      link
      fedilink
      English
      20
      edit-2
      5 months ago

      the article links to this list of repos https://files.catbox.moe/jx7ksm.txt and says is 6200 lines long.

      i am not framiliar enough with this kind of development to know if this is a reasonable structure for this kind of large project. anyone?

      • flan [they/them]
        link
        fedilink
        English
        18
        edit-2
        5 months ago

        Looks like they put each of their modules in a separate repo. This wouldn’t be a single project. NYTimes is a pretty huge operation. They obviously have their website but they also have apps, infrastructure to ingest and process whatever media they get, infrastructure for ads, games, security (lol), user account management, billing, legal, etc etc.

        it’s possible this is organized differently in their source control and it appears kinda disorganized because we’re looking at it flattened.

    • blobjim [he/him]
      link
      fedilink
      English
      11
      edit-2
      5 months ago

      It’s probably just every repository name on their spurce control management server. Users can usually create their own repositories whenever. So a bunch if these could just be random little experiments or side projects people made.